CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5521

As cited

Copy frozen at (site build).

research

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Stratus Security released Sift, a free open-source command line tool that searches for sensitive data including passwords and application programming interface (API) keys across enterprise systems. The scanner covers local storage, file shares, Active Directory, Microsoft 365 services (SharePoint, OneDrive, Teams), Slack messages, and Jira/Confluence. The firm developed Sift internally for penetration testing engagements and published it publicly.

Why it matters: Security teams and penetration testers need visibility into where credentials are exposed across the SaaS and enterprise tools their organizations rely on; Sift provides a free way to audit these platforms for secrets that could enable lateral movement.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

research

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Stratus Security released Sift, a free open-source command line tool that searches for sensitive data including passwords and application programming interface (API) keys across enterprise systems. The scanner covers local storage, file shares, Active Directory, Microsoft 365 services (SharePoint, OneDrive, Teams), Slack messages, and Jira/Confluence. The firm developed Sift internally for penetration testing engagements and published it publicly.

Why it matters: Security teams and penetration testers need visibility into where credentials are exposed across the SaaS and enterprise tools their organizations rely on; Sift provides a free way to audit these platforms for secrets that could enable lateral movement.

VendorsMicrosoftAtlassianSlack
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary